]> git.ipfire.org Git - thirdparty/openssl.git/commit
ctr-drbg: always use the DF for OpenSSL's DRBGs
authorPauli <ppzgs1@gmail.com>
Mon, 23 Sep 2024 04:45:41 +0000 (14:45 +1000)
committerTomas Mraz <tomas@openssl.org>
Tue, 24 Sep 2024 15:53:26 +0000 (17:53 +0200)
commit260ecea0d4e46d63464636405f9925ef65d0747e
tree461886b3751b79b9b7d63304bf472cea7e8f983e
parent9d71a6622be15592ad75dd4e6c5816c9042611e9
ctr-drbg: always use the DF for OpenSSL's DRBGs

Force the use of the derivation function when creating OpenSSL's internal
DRBGs.

FIPS mandates the use of a derivation function, so 3.4 cannot be validated as
it stands which run counter to the indicator work that was included.

Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tom Cosgrove <tom.cosgrove@arm.com>
Reviewed-by: Hugo Landau <hlandau@devever.net>
(Merged from https://github.com/openssl/openssl/pull/25511)

(cherry picked from commit 0ab796ef9674b378ac644ad8d477685619a2ff37)
crypto/rand/rand_lib.c